CVE-2020-1698

MEDIUM5.5EPSS 0.05%

Keycloak leaks sensitive information in logged exceptions

Published: 5/24/2022Modified: 4/22/2024
Also known as:GHSA-qgmm-f2qw-r95f

Description

A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (4)